faisalman / ua-parser-js

"Unmask Your Traffic" - UAParser.js: The Essential Web Development Tool for User-Agent Detection
https://uaparser.dev/
GNU Affero General Public License v3.0
9.28k stars 1.2k forks source link

Vulnerability sonatype-2018-0272 #615

Closed LucasLopesr closed 1 year ago

LucasLopesr commented 1 year ago

I'm getting the indication of vulnerability in this package, has anyone checked it yet? is this safe?

https://ossindex.sonatype.org/vulnerability/sonatype-2018-0272?component-type=npm&component-name=ua-parser-js&utm_source=dependency-track&utm_medium=integration&utm_content=v4.4.2

faisalman commented 1 year ago

This has been fixed in https://github.com/faisalman/ua-parser-js/commit/50bd78afb140136deef245dcf95052bd8f0bc27e